2026 CVE Vulnerabilities
56,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57793 | HIGH | 7.5 | 0.5% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57792 | HIGH | 7.5 | 0.5% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57791 | HIGH | 7.5 | 0.5% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57790 | HIGH | 7.5 | 0.5% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57789 | HIGH | 7.5 | 0.5% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57788 | HIGH | 7.5 | 0.5% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57787 | HIGH | 8.5 | 0.3% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVG... |
| CVE-2026-57786 | HIGH | 8.8 | 0.2% | Jul 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass... |
| CVE-2026-57783 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker ... |
| CVE-2026-57782 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Confi... |
| CVE-2026-57781 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-57780 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision En... |
| CVE-2026-57779 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Con... |
| CVE-2026-57778 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exp... |
| CVE-2026-57776 | MEDIUM | 5.3 | 0.4% | Jul 13, 2026 | Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-57774 | MEDIUM | 5.3 | 0.4% | Jul 13, 2026 | Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured A... |
| CVE-2026-57773 | HIGH | 7.6 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shi... |
| CVE-2026-57772 | HIGH | 8.5 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP In... |
| CVE-2026-57771 | HIGH | 8.5 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD ... |
| CVE-2026-57770 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection... |
| CVE-2026-57768 | HIGH | 8.2 | 0.3% | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege ... |
| CVE-2026-57745 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18... |
| CVE-2026-57744 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injecti... |
| CVE-2026-57743 | HIGH | 8.1 | 0.6% | Jul 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-57741 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newslet... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now